PT-2022-23315 · Insyde · Insydeh2O

Published

2022-09-23

·

Updated

2022-09-27

·

CVE-2022-36338

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O versions 5.0 through 5.5
Description An issue was discovered in Insyde InsydeH2O, where an SMM callout vulnerability in the SMM driver FwBlockServiceSmm leads to arbitrary code execution. This occurs when creating SMM, allowing an attacker to replace the pointer to the UEFI boot service GetVariable with a pointer to malware and then generate a software SMI.
Recommendations For versions 5.0 through 5.5, consider disabling the SMM driver FwBlockServiceSmm as a temporary workaround until a patch is available. Restrict access to the UEFI boot service GetVariable to minimize the risk of exploitation. Avoid using the GetVariable service in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-36338

Affected Products

Insydeh2O